Lucene search

K
kasperskyKaspersky LabKLA64088
HistoryFeb 20, 2024 - 12:00 a.m.

KLA64088 Multiple vulnerabilities in Mozilla Firefox

2024-02-2000:00:00
Kaspersky Lab
threats.kaspersky.com
15
mozilla firefox
vulnerabilities
sensitive information
denial of service
arbitrary code
update
latest version

9.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.5%

Multiple vulnerabilities were found in Mozilla Firefox. Malicious users can exploit these vulnerabilities to obtain sensitive information, cause denial of service, spoof user interface, execute arbitrary code, gain privileges, bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. Invalid memory access vulnerability in the built-in profiler can be exploited to obtain sensitive information.
  2. Out-of-bounds memory read in networking channels can be exploited to cause denial of service.
  3. Information disclosure vulnerability in cache can be exploited to obtain sensitive information.
  4. Security UI vulnerability in Fullscreen Notification can be exploited to spoof user interface.
  5. Memory safety vulnerability can be exploited to execute arbitrary code.
  6. An elevation of privilege vulnerability can be exploited remotely to gain privileges.
  7. Information disclosure vulnerability can be exploited to obtain sensitive information.
  8. Security UI vulnerability can be exploited to spoof user interface.
  9. Security vulnerability can be exploited to bypass security restrictions.

Original advisories

MFSA2024-05

Related products

Mozilla-Firefox

CVE list

CVE-2024-1556 warning

CVE-2024-1546 warning

CVE-2024-1554 warning

CVE-2024-1548 warning

CVE-2024-1557 warning

CVE-2024-1550 warning

CVE-2024-1551 warning

CVE-2024-1547 warning

CVE-2024-1555 warning

CVE-2024-1549 warning

CVE-2024-1552 warning

CVE-2024-1553 warning

Solution

Update to the latest version

Download Firefox

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

  • DoS

Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.

  • SB

Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.

  • PE

Privilege escalation. Exploitation of vulnerabilities with this impact can lead to performing by abuser actions, which are normally disallowed for current role.

  • SUI

Spoof user interface. Exploitation of vulnerabilities with this impact can lead to changes in user interface to beguile user into inaccurate behavior.

Affected Products

  • Mozilla Firefox earlier than 123